The FortiWeb web application firewall (WAF) defends web-based applications from known and zero-day threats. Its AI-based machine learning identifies threats with virtually no false positive detections.
Whether to simply meet compliance standards or to protect mission critical hosted applications, FortiWeb Web Application Firewalls (WAFs) provide advanced features and AI-based machine learning detection engines that defend web applications from known and zero-day threats.
Using a multi-layered and correlated approach, FortiWeb intelligently and accurately protects your web applications from the OWASP Top 10 threats. Combined with Fortinet Web Application Security Service from FortiGuard Labs, FortiWeb keeps your applications safe from vulnerability exploits, bots, malware uploads, DoS attacks, advanced persistent threats (APTs), and zero day attacks.
FortiWeb software editions offer the same features of the FortiWeb hardware-based appliances with the flexibility to deploy instances as needed to meet the demands of dynamic application hosting environments.
Highlights
EFFECTIVE protection using multiple techniques including signatures, IP reputation, antivirus, and AI-based behavioral analysis and bot mitigation
INTEGRATED with FortiGate, FortiSandbox, and leading third-party vulnerability scanners for enhanced zero-day threat protection and virtual application patching
ACCURATE with intelligent tools that minimize false positive detections including user scoring, session tracking, and event correlation
Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 15 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
Fortinet FortiWeb Web Application Firewall WAF (PAYG)
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You pay by the hour for FortiWeb running as a Web Application Firewall on AWS. Pricing follows the AWS EC2 instance type you choose to run the software. Each dimension names a specific instance size across the t3, c4, c5, m3, m4, m5, and r5 families. Smaller instances handle lighter traffic; larger instances add compute, memory, or network capacity for heavier workloads. Your hourly software rate scales with the instance size selected. This usage-based model means you run instances as needed and stop paying when you shut them down. No upfront commitment applies.
Top-of-mind questions for buyers
Am I charged for a FortiWeb instance while it is stopped or powered off?
You pay the hourly software rate only while the instance runs. When you stop or shut down the instance, the software charge stops. Underlying AWS resources like attached storage may still bill separately, but the FortiWeb software meters running hours only.
What does the instance type I pick actually determine for FortiWeb?
Each dimension maps to one AWS EC2 instance size across the t3, c4, c5, m3, m4, m5, and r5 families. The instance sets the compute, memory, and network capacity available to FortiWeb. Larger instances handle heavier web application traffic; smaller ones suit lighter loads.
How does this hourly usage model differ from committing upfront?
This listing meters actual instance-hours with no upfront commitment. You run instances as needed and stop paying when you shut them down. This suits variable or short-term workloads. A separate bring-your-own-license option exists but is not part of this usage-based listing.
docs.fortinet.com+1
Helpful?
Vendor refund policy
You may terminate the instance at anytime to stop incurring charges.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
After deploying the instance, click on 'Manage in AWS Console' to see the running instance and public DNS address to continue the configuration of the FortiWeb-VM. Connect to the secured Web UI via the public DNS address: https://Public DNS:8443. For any CLI configuration/settings, SSH is required to log into the CLI. Default login credentials are with a username of "admin" and the AWS Instance ID value as the password. The FortiWeb-VM Install and Configure guides is located at https://docs.fortinet.com/vm/aws/fortiweb. For the full FortiWeb Administrator Guide, please refer to Fortinet documentation: https://docs.fortinet.com/fortiweb/admin-guides